A signed JWT (RFC 7519, using the JWS format from RFC 7515) is three Base64URL strings joined by dots:
header.payload.signature
header {"alg":"HS256","typ":"JWT"} -> eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9
payload {"sub":"user_8f3a2c71","exp":4102444800} -> eyJzdWIiOiJ1c2VyXzhmM2EyYzcxIiwiZXhwIjo0MTAyNDQ0ODAwfQ
signature HMAC-SHA256(header + "." + payload, secret), Base64URL-encoded
The header names the signing algorithm (alg) and often a key
ID (kid) that tells the verifier which key to use. The payload
holds the claims. The signature is computed over the exact first two
segments, so changing a single character in either one invalidates it. Since every
eyJ you see is just {" in Base64,
the header and payload are readable by anyone who holds the token.
A token with five segments is a JWE, an encrypted JWT. Its payload is ciphertext, and no decoder can show it without the recipient's key.